Droppers Exploiting CVE-2017-11882 — Detection Rule

Detects exploits that use CVE-2017-11882 to start EQNEDT32.EXE and other sub processes like mshta.exe

Read the full analysis on IntelFusions